need to close or escape the single quote in mysql

     foreach($_POST['id'] as $id =>$v){
     //echo '<br>post foreach update';   
        $q = 'update '.$tablename.' set ';
        foreach ($cols as &$columnname) {
          $q.=$columnname.'=\''.$_POST[$columnname][$id].'\',';
          }        
        $q = substr($q,'',-1);
        $q.=' where id='.$_POST['id'][$id].'';
        echo '<br>'.$q;
        mysql_query ($q); 
 }

Open in new window



if the post contains
'

example
sally's
friend's
james'
she said, 'this'

the query will not work
LVL 1
rgb192Asked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
Dave BaldwinConnect With a Mentor Fixer of ProblemsCommented:
"mysql_real_escape_string" or the newer versions are used to 'escape' quotes and other problem characters before they are inserted into a MySQL database.
http://php.net/manual/en/function.mysql-real-escape-string.php
0
 
rgb192Author Commented:
this escaped '
thanks
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.